Home/News/Arista Patches VeloCloud Orchestrator Zero-Day Exploited in Attacks
BleepingComputer3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Arista Patches VeloCloud Orchestrator Zero-Day Exploited in Attacks

Arista Networks has addressed a critical command injection vulnerability within its VeloCloud Orchestrator software, a platform used for managing SD-WAN (Software-Defined Wide Area Networking) deployments. This vulnerability, classified as maximum severity, allowed attackers to inject arbitrary commands into the system, potentially leading to unauthorized access and control. The company confirmed that this zero-day flaw was actively exploited in the wild before a patch was made available, highlighting the immediate threat to organizations utilizing the affected on-premises VeloCloud Orchestrator deployments.

The vulnerability, identified as CVE-2024-3155, resides in the VeloCloud Orchestrator's handling of specific API requests. Attackers could leverage this flaw by sending specially crafted input to the orchestrator, bypassing security measures and executing malicious commands with elevated privileges. The exploitation of this vulnerability could have far-reaching consequences, including the potential for data exfiltration, system disruption, and the deployment of further malware within a compromised network. Arista Networks has not disclosed the exact number of affected customers or the specific nature of the attacks observed, but the active exploitation indicates a sophisticated threat actor or actors.

Arista Networks strongly advises all users of on-premises VeloCloud Orchestrator deployments to apply the provided security update immediately. The company's security advisory details the affected versions and provides instructions for the patching process. While the cloud-hosted VeloCloud Orchestrator service is not impacted by this specific vulnerability, organizations relying on the on-premises solution must prioritize this update to mitigate the risk of compromise. The rapid patching and disclosure underscore the importance of proactive security measures and timely vendor responses to emerging threats in the complex landscape of network management software.

This incident serves as a stark reminder of the persistent threats posed by zero-day vulnerabilities, particularly in widely deployed network infrastructure components. The VeloCloud Orchestrator is a key component for enterprises managing their network edge and WAN connectivity, making its compromise a significant security concern. The ability for attackers to exploit such vulnerabilities before vendors are aware or have released fixes necessitates a robust security posture, including continuous monitoring, prompt patching, and layered security defenses. Arista's swift action in releasing a patch, despite the active exploitation, is a positive step in protecting its customer base from further harm.

Original source — read the full reporting at the publisher:

Read on BleepingComputer

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next